Security Scan Report: copier.pk

Submitted: Sep 14, 2026, 2:13:21 PMCompleted: Sep 14, 2026, 2:14:01 PMpubliccompleted

This website contacted 6 IPs in 2 countries across 4 domains to perform 6 HTTP transactions. The main domain is copier.pk and was registered 14 years ago.

Submitted URL: https://copier.pk/product-tag/rawalpindi/?srsltid=afmboooxrxqhx_9ww69ykky56icefwef6mx2d4cyfge187mr1rfxw8ui

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Legitimate printing-equipment site copier.pk appears compromised with a ClearFake Polygon contract loader, a critical malware/phishing kit. Do not interact until cleaned.

Risk Factors (3)
ClearFake malware loader injected into page (Polygon smart contract EtherHiding C2)
Known malicious kit family clearfake-polygon-loader-2026-10
Inline script encoding/decoding functions and IDS obfuscator heuristic alerts corroborate suspicious JavaScript
Domain age information unavailable

Details

Page Title

Rawalpindi – Copier Pk

Scan Type

public

Domain Name Analysis

The domain 'copier.pk' uses the Pakistani country-code top-level domain (.pk) without a subdomain. Count 6 characters in 'copier' holding three vowels versus three consonants. Word splitting yields 1 word: copier. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://copier.pk/product-tag/rawalpindi/?srsltid=afmboooxrxqhx_9ww69ykky56icefwef6mx2d4cyfge187mr1rfxw8ui

Page Load Overview

0.46s
Total Load Time
79 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:3,507 chars
Detector Agreement:50%

Website Classification

Primary Category

forum40% confidence
Type: spa
Method: structural

All Detected Categories

forum
40%
e-commerce
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
192.113.16.192Frankfurt am Main, Hesse, Germany
AS47583Hostinger International Limited
1142.251.110.97Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1192.178.170.95Google · CDNUnited States
AS15169Google LLC
192.113.23.58Frankfurt am Main, Hesse, Germany
AS47583Hostinger International Limited
192.113.16.218Frankfurt am Main, Hesse, Germany
AS47583Hostinger International Limited
66--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E5D2C633E05940BB3B9F97BCD2957328E689A600CB427BB6F0F4617856945FB00B7A0D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:zRpxMdrZdypa2IawyPtL7xVONrd1cFm7QvoS:NvMxyppwyPtL7xVONrd1cFm7QvoS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29435:IGIE9qiKypYADhBqAICkCAyspkQtEQ4cycYAUCBNoICgsJQpDJqmiAiieEAZUJEe6AhEBAihBFKAIWwRFJE0DfUA1AXAQRUY

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00fff1f1fff1fdfe
Perceptual Hash:ed0d1212576b6d17
Difference Hash:630047434c150916
Wavelet Hash:00fff1e1e1d1d5c0
Color Hash:#3a786b

Scan History

Scan history not available

Unable to load historical scan data